CVE-2024-34074: Frappe

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.

Affected products

  • Frappe Frappe: before 14.74.0 (fixed in 14.74.0); from 15.0.0, before 15.26.0 (fixed in 15.26.0)

Published 2024-05-14. Last modified 2026-06-17.